Program Removed
This program is no longer available on YesWeHack. The scope data shown below is historical and may not reflect the final state of the program.
keycloak-bug-bounty-program
6
In Scope
5
Out of Scope
In-Scope Assets (6)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| javascript client adapter | OPEN-SOURCE | Yes | - | |
| javascript client adapter | OTHER | Yes | - | |
| keycloak operator | OTHER | Yes | - | |
| keycloak operator | OPEN-SOURCE | Yes | - | |
| keycloak server | OTHER | Yes | - | |
| keycloak server | OPEN-SOURCE | Yes | - |
Out-of-Scope Assets (5)
| Asset | Category | Bounty | |
|---|---|---|---|
| any asset that is not explicitly included in our program's scope | OTHER | Yes | |
| any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rules | OTHER | Yes | |
| any local implementation of the project/implementation belonging to third parties | OTHER | Yes | |
| any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages) | OTHER | Yes | |
| experimental features | OTHER | Yes |
Scope Changes (30)
Mar 6, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Program Removed | — | — | — | 16:39 |
Feb 25, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | javascript client adapter | OPEN-SOURCE | In Scope | 19:08 |
| Added | any asset that is not explicitly included in our program's scope | OTHER | Out of Scope | 19:08 |
| Added | any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages) | OTHER | Out of Scope | 19:08 |
| Added | any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rules | OTHER | Out of Scope | 19:08 |
| Added | any local implementation of the project/implementation belonging to third parties | OTHER | Out of Scope | 19:08 |
| Added | experimental features | OTHER | Out of Scope | 19:08 |
| Added | keycloak server | OPEN-SOURCE | In Scope | 19:08 |
| Added | keycloak operator | OPEN-SOURCE | In Scope | 19:08 |
Feb 22, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | javascript client adapter | OTHER | In Scope | 00:51 |
| Added | any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rules | OTHER | Out of Scope | 00:51 |
| Added | any local implementation of the project/implementation belonging to third parties | OTHER | Out of Scope | 00:51 |
| Added | experimental features | OTHER | Out of Scope | 00:51 |
| Added | keycloak server | OTHER | In Scope | 00:51 |
| Added | keycloak operator | OTHER | In Scope | 00:51 |
| Added | any asset that is not explicitly included in our program's scope | OTHER | Out of Scope | 00:51 |
| Added | any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages) | OTHER | Out of Scope | 00:51 |
Feb 21, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Removed | keycloak server | OPEN-SOURCE | In Scope | 21:40 |
| Removed | keycloak operator | OPEN-SOURCE | In Scope | 21:40 |
| Removed | javascript client adapter | OPEN-SOURCE | In Scope | 21:40 |
| Removed | any asset that is not explicitly included in our program's scope | OTHER | Out of Scope | 21:40 |
| Removed | any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages) | OTHER | Out of Scope | 21:40 |
| Removed | any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rules | OTHER | Out of Scope | 21:40 |
| Removed | any local implementation of the project/implementation belonging to third parties | OTHER | Out of Scope | 21:40 |
| Removed | experimental features | OTHER | Out of Scope | 21:40 |
| Added | any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages) | OTHER | Out of Scope | 00:33 |
| Added | any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rules | OTHER | Out of Scope | 00:33 |
| Added | any local implementation of the project/implementation belonging to third parties | OTHER | Out of Scope | 00:33 |
| Added | experimental features | OTHER | Out of Scope | 00:33 |
| Added | any asset that is not explicitly included in our program's scope | OTHER | Out of Scope | 00:33 |